An issue was discovered in the Linux kernel through 4.17.10. There is a use-after-free in try_merge_free_space() when mounting a crafted btrfs image, because of a lack of chunk type flag checks in btrfs_check_chunk_valid in fs/btrfs/volumes.c.
4.4.0-1040.434.4.0-144.170~14.04.14.4.0-145.1714.4.0-1079.894.15.0-1047.49~16.04.14.15.0-1055.604.15.0-1040.42~16.04.14.15.0-58.64~16.04.14.4.0-1043.494.15.0-1021.23~16.04.1Exploitability
AV:LAC:LPR:NUI:RScope
S:UImpact
C:NI:NA:HCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H